review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
gitandgh(GitHub CLI) binaries to perform repository operations such as fetching remotes, creating branches/worktrees, and querying Pull Request metadata. These executions are necessary for the skill's stated purpose and are guarded by identity checks to ensure operations are confined to the intended PR context. - [INDIRECT_PROMPT_INJECTION]: As the skill ingests Pull Request titles, bodies, and issue comments, it is exposed to untrusted data. The skill mitigates this risk by explicitly instructing the agent to treat this content as evidence rather than executable instructions, and it maintains a 'bodies_collected' status to track evidence coverage without granting the data instruction-level authority. (Internal Severity: LOW).
- [DYNAMIC_EXECUTION]: The
prepare-pr-branch.shscript employs an embedded Python heredoc for metadata processing. This dynamic execution is used for structured parsing and sanitization, applying strict regex patterns ([A-Za-z0-9][A-Za-z0-9-]*) to validate repository owners and branch names before they are used in shell commands. - [DATA_EXPOSURE_EXFILTRATION]: The skill manages review evidence using a local snapshot protocol (
snapshot_transport.py). Snapshots are stored with restrictive file permissions (0600) and verified using SHA-256 fingerprints to ensure integrity and prevent unauthorized access or tampering within the local filesystem. - [EXTERNAL_DOWNLOADS]: The skill performs remote fetches via Git. These operations are restricted to the PR's base and head repositories as determined by the GitHub API, utilizing trusted
github.cominfrastructure.
Audit Metadata